Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

466 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.43%—Tensoropera FedmlAI14/9/202614/9/2026
A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote…
Pendiente de análisisAlta (7.7)0.40%—Tensorzero GatewayAI21/8/202611/9/2026
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage]…
En análisisMedia (5.4)0.16%—Intel Extension FOR TensorflowAI11/8/202612/8/2026
Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
AplazadaMedia (6.2)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.4)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
AplazadaAlta (7.8)0.35%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.
AplazadaAlta (7.5)0.31%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.
AplazadaMedia (6.2)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.8)0.21%—Nvidia Tensorrt14/7/202617/7/2026
NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution.
AplazadaMedia (6.2)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.8)0.22%—Nvidia Tensorrt14/7/202617/7/2026
NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.
AplazadaMedia (6.4)0.18%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
AnalizadaAlta (7.8)0.21%—Nvidia Tensorrt14/7/202617/7/2026
NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution.
AplazadaMedia (6.8)0.15%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
AplazadaAlta (8.4)0.39%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data…
AplazadaAlta (7.3)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and…
AnalizadaCrítica (9.8)1.0%—Nvidia Tensorrt14/7/202617/7/2026
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.
AplazadaMedia (6.3)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
AnalizadaMedia (6.4)0.33%—Nvidia Tensorrt-llm14/7/202622/9/2026
NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.
AnalizadaAlta (7.5)0.39%—Nvidia Tensorrt20/5/202623/7/2026
NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.
AnalizadaCrítica (9.8)0.59%—Nvidia Tensorrt LLM20/5/202624/7/2026
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.
AnalizadaAlta (7.5)0.47%—Nvidia Tensorrt LLM20/5/202624/7/2026
NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaCrítica (9.8)0.38%—Nvidia Tensorrt LLM20/5/202624/7/2026
NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
AnalizadaCrítica (9.8)0.57%—Nvidia Tensorrt LLM20/5/202624/7/2026
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.
AnalizadaMedia (6.9)0.62%—Tensoropera Fedml5/4/202624/7/2026
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not…